CVE-2020-12819
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 19, 2024
CWE ID 122
Summary
CVE-2020-12819 is a heap-based buffer overflow vulnerability affecting FortiGate versions 5.6.12, 6.0.10, 6.2.4, and 6.4.1, and earlier. This issue is found in the processing of Link Control Protocol (LCP) messages in FortiGate's SSL VPN daemon. A remote attacker with valid SSL VPN credentials can exploit this vulnerability by sending a large LCP packet while tunnel mode is enabled. The impact includes crashing the SSL VPN daemon, with arbitrary code execution being theoretically possible, although practically very challenging to achieve in this context.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiOS
Affected Vendors
- Fortinet